Most companies trust their website. They shouldn't. The leaders who know better are rebuilding what it means to govern a website, and every week we sit down with privacy executives, compliance teams, and digital risk pros at the world's largest enterprises.
We dive into stories with the ones who caught a broken consent tool before the regulator did, traced a six-figure loss back to a failed tracking pixel, and rebuilt their entire data governance approach from scratch. The rules of digital trust are being rewritten right now. This show is where you hear it first.
Brought to you by ObservePoint, the web governance platform that helps the world's largest enterprises see exactly what their websites are doing, and prove it.
The Web Privacy Podcast - Erin McCurdy
===
Erin McCurdy: [00:00:00] I always say that my job is to support you, what do you need from me? And if you take that approach and you don't sit in an ivory tower, it is very well received. I'm a partner to them. Like my job is to make them do their job more efficiently and compliantly
Ethan Prete: Good morning, good afternoon, and good evening, privacy professionals alike, and welcome to the Web Privacy Podcast, where I fulfill my dream of simplifying the web privacy space by bringing together privacy professionals from all over the world to share cutting-edge ideas. I'm your host, Ethan Prete, and today we're joined by Erin McCurdy, Chief Privacy Officer and Data Protection Officer at Synopsys.
Erin holds virtually every major credential in the privacy space, and I'm gonna take a breath here because this list is pretty long. This includes her FIP, her CIPM, and multiple CIPP designations. She also has extensive experience navigating complex global acquisition hurdles in the software industry, which we'll talk about in depth today.
And then obviously, as we all know, in the M&A [00:01:00] transaction space, speed is everything. Everybody wants to move that deal fast, but over-sharing personal data too early is one of the quickest ways to create massive regulatory liability before the ink on that deal is even dry. So today, we're sitting down with Erin to unpack the if, what, when, and how of sharing personal data across the M&A life cycle.
Erin, to kick us off, if there's anything that I have learned over the past few years being in this space, it's that the pathway to becoming a chief privacy officer is always unique. Each person forges their own journey. They're not waking up in the morning thinking, "Man, I should start becoming a chief privacy officer."
And I feel like at times I could label this as almost the Island of Misfit Toys. So if you wouldn't mind, to kick us off would you mind sharing with us a bit about who you are, where you live? If you have any hidden talents legally, you do have to share those with me, and also your journey to becoming a CPO at Synopsys.
Erin McCurdy: Okay, lovely. First of all, I'd like to thank you for inviting me to the podcast. I'm super excited to talk about my experiences. I've been an attorney for about 20 years, and I started as a generic [00:02:00] commercial attorney in Pittsburgh, Pennsylvania, where I went to law school, and loved it.
And eventually, I was drafted to become an in-house attorney, actually an e-commerce technology attorney with Dick's Sporting Goods. And while I was there, being the e-commerce attorney, I had the ability to review their privacy policy and understand their marketing consents. And it-- this was early 2000s.
This is when the GDPR was not yet the law. Dick's was a US-based company, so that we were dealing with the FTC Article 3 violations, basically, okay? So it was very different from what we have today. And I was fortunate enough to be recruited away from Dick's to go in-house with American Eagle to become their privacy officer because of the work that I'd been doing with Dick's.
I loved working at American Eagle, great company. There I was their technology and privacy officer. And then I was recruited away again to go in-house with Ansys Inc. As their global privacy officer. So I kept growing my realm of what I was responsible for. And being their global privacy officer, Synopsys [00:03:00] Inc.
purchased Ansys Inc. in July of '25. So we just completed our first year. And I was fortunate enough once we were integrated to get the top position of the chief privacy officer, and it has been an amazing learning experience. I've enjoyed it, and my realm of responsibilities has continued to grow.
But it was a... For being such a niche area, it was actually a pretty direct path, and I fell into privacy by accident when I was the e-commerce attorney and needed to worry about the privacy notice. And I just realized that this is an opportunity. And one of the things that I pride myself on is being a truly business-friendly privacy attorney, which I think is a challenge.
I think that a lot of privacy attorneys get very stuck in the compliance realm, and really you f- sometimes I believe they forget that, the business still needs to make money. So I try to be an asset and an enabler in my role.
Ethan Prete: That's incredible, and it sounds like one of your hidden talents is working with companies from my childhood, so there's some nostalgia coming up for me there.
Erin McCurdy: Love that, right?
Ethan Prete: That's right. [00:04:00] And I appreciate you sharing that. And one of the things I've seen as well, and as you mentioned, you weren't exactly thinking that this was the direction you would take, but you saw the opportunity, and that's not an uncommon story.
And so I'm curious as well. It feels like the chief privacy role has existed for 25 plus years, but you even called this out, GDPR coming up in 2018 and then now, CCPA and all the regulations that are following that. It feels like people are figuring it out now in the new landscape.
So I'm curious as you look across your team, your responsibilities, what do your responsibilities at Synopsys entail, and what does your team composition look like?
Erin McCurdy: Okay, I'm happy to talk about this. So I just want to circle back to one other comment. You said that I don't think a lot of people start out their careers thinking they're gonna be a chief privacy officer. I agree. In my day, that was the truth, but I hope it's different now. They have privacy classes in law school and such, so I'm hoping that people are, like, flocking to the profession because- there's a definite need for privacy professionals.
But regarding my team is... i'm responsible for a large portion of in the tech do-data IT, cybersecurity [00:05:00] space, so from a legal perspective. So I'm fully responsible for privacy regarding the operational business and legal side of it. So I have a privacy team that I'm responsible for the entire company.
And then I like to think of it as that's my job. I do all of it from soup to nuts, and I try to really engage with team members in the different teams, and I treat them as an extension of my team, and we educate them, and we have them as issue spotters. Outside of that, I'm also the attorney responsible for cybersecurity, IT, marketing law, crisis management, and I'm actually the secretary for the foundation as well, which makes me happy.
I love doing nonprofit work. So that's my world. We have it's very tech data-driven for us, and we have a team of individuals. I have - attorneys and non-attorneys underneath me. I have attorneys dedicated to privacy and to cybersecurity and IT, and then I have professionals dedicated more in the privacy space than the other spaces.
We actually have data usage and data [00:06:00] management oversight as well. So that's where we have a non-attorney professional in that space as well. So all of those things come together for the world. I think what everyone will complain about is we wish we had more staff and m- more resources, but we make it work.
I like to say that we run lean, but we run fast, I think
Ethan Prete: Love that. I'm glad it's not just my team hoping for more resources. I think that's
Erin McCurdy: think we all are, right?
Ethan Prete: It's everywhere you go. I love it, and thank you for sharing. And,
Erin McCurdy: Of course.
Ethan Prete: I've been thinking this whole time and full transparency here, I was able to chat with Erin a little bit before we jumped on the podcast, getting to know her, and I just, I was blown away.
And what I'm thinking as I'm talking to her is, if I had to guess what my skill set was as a marketer to put me in the top 1%, unfortunately, the only things that I could think of included things like being good at the TV show "Jeopardy!" and also the everyday phone game where you guess the geography, Map Tap.
Those are really the only things that I'm, like, maybe in the top 1% of. And as I'm looking at you and hearing you talk and your resume, you s- you clearly have tangible skills related to your [00:07:00] field of work. The one I wanna start with, as we mentioned before, was mergers and acquisitions. Many companies assume that their general customer or employee privacy notices give them a blanket pass to share during data during the the M&A process.
And as I've learned reading your papers and things, that is a very dangerous assumption. Would you wanna quickly jump into why that is?
Erin McCurdy: Sure, of course. Just to give a little bit of perspective, when I was at Ansys, we acquired three to five companies a year, so we were on ac-acquisition side, which is the preferred method, right? You're in the driver's seat. So I like being on the driver's seat. And so I was very heavily involved in the integration, in the purchase, and the negotiation of those deals to make sure that the data that we're bringing in goes in the proper place, that we're getting it at the appropriate time.
But more recently, Synopsys bought Ansys for $32 billion in July. Massive transaction, huge regulatory approvals necessary. And in that situation, for the first time, I was on the sell side. I learned so much being on the sell side, but I was heavily involved. I was part of the [00:08:00] integration team. I was heavily involved in so many of the discussions, and for the first time, I was on the side of sharing the data, not the company that would ultimately own everything in the end.
Now, once we integrated, I got the job, so then I became responsible for it. But at the time, being on the sell side, it was very interesting to hear a lot of the requests that were coming through and trying to understand at what point should we share which data? Do we have a legal basis to share this data for this purpose?
What's the usage? So there's a whole lot of time and effort that goes into being the gatekeeper of the data. Ultimately, I understand that in the end, the company will own that data, but there are situations when companies don't close, and then you've overshared the data, which you don't have the legal right to share at that point.
So you have to be very thoughtful about what is the point of the transaction, what information you are sharing, and for what purpose.
Ethan Prete: Sure. And you just gave us two different examples, one of which in which you were the seller. Before a seller transmits a single row of personal data, do you have a [00:09:00] three non-negotiables that you feel like need to be in place behind the scenes?
Erin McCurdy: Yeah I do. So basically, the very starting point is gonna be the data protection agreement. You need to have a data protection agreement in between the parties. It needs to be thoroughly negotiated and understood what are you sharing at what point. Unfortunately, those documents end up being pretty high level often because the data will be shared, so they don't always talk about at what point you should share.
And that's fine because a lot of times you don't know how the transaction's gonna go. Sometimes they go quickly, sometimes they drag out. So timing doesn't have to be in the DPA, but you have to have the DPA as your basis to even begin to share that information. Then once you begin to share the information, you have to have an understanding of why are they asking, what are they gonna use it for, and what am I going to share?
So it's very common for companies to overshare because they think that, "Okay, they're gonna buy us anyway, we can share it all." That's not the point. - We're gonna talk through some different timing, I think. So we'll get to those specifics shortly, but it's on you as the sell side to protect that data.
When [00:10:00] you collected that data, you did so for a specific purpose, and you were given specific information at the time of collection to that individual. So okay, at that point, it's your job to be very cautious and very detailed in sharing. The third non-negotiable, I think, is probably can you even share it?
So most of the time, companies gather the right to share that data right in their public-facing privacy notice for their customers and then for their employees. So within those documents, if you have that information listed, which basically is broken down into what data are you collecting, why are you collecting it, how are you gonna share it?
Within that how are you gonna share it, there's usually a blanket statement that says, "In furtherance of M&A acquisitions, transaction, mergers, et cetera, we have the right to share your document, your data." So it's clearly listed there. When you don't have that, it's a lot different situation, but in this point, it's industry standard to have those clauses and those notices.
Ethan Prete: That makes a lot of sense. And I should have mentioned this before, but I feel like this topic, again, I find it to be so [00:11:00] relevant given just the state of the industry as well as the individuals that we all, interact with in the privacy space whether at conferences or literally from job to job.
And I'm thinking back even to like the, the days of the ZIRP, the zero interest rate policies, where M&A was interesting because there were such high asking prices. And now, I don't have my stats in front of me, but it feels like, again, these mega deals you're talking about are becoming more common.
The $32 billion, I believe, was the number you referenced earlier.
Erin McCurdy: It's PHDO, yes.
Ethan Prete: So again, due diligence is critical,
Erin McCurdy: We did not wanna be in regulatory situation that we overshared too early. And now being with the company the practices that we adopted during that are still the practices with the company. So The goal is to educate the individuals on, when, ones that are asking. Make sure they understand what they should be asking for and when, and that's not a difficult thing to do.
The, it's basic, it's very factual. It's also very need-driven. So if you can educate those individuals and get people comfortable that you don't need to share everything out of the gate, and also the team sharing. A lot of times if [00:12:00] you leave it to uh, some- it's lower IT person to share the information, they'll just share the file, and that's not right either.
A lot of times I've been reviewing show me the list of the files. What's going over? Let me see the columns. Why do they need this? Why do they need this?" And we have them limit that down and redact to share only what really is necessary
Ethan Prete: Sure. Going into that though, 'cause again, I, you had mentioned like knowing what to share, when to share, et cetera. The first question that comes to my mind is, even after an NDA is signed, you typically have the buyer coming and asking for all of their due diligence requests.
Things like itemized employee salary lists, customer accounts, et cetera. And it sounds like what you're saying is you're able to push back on some of this. Is that the case for the seller?
Erin McCurdy: Absolutely. When you are just under an NDA, and this is the point in time where the companies are just determining, "Hey, does this acquisition make sense? Are our products gonna overlap enough? Is this gonna make us enough money? What are the markets that we're both in?" Personal data, unless your business is the sale of personal data, which is not the [00:13:00] majority of the situation, so we're not talking about that situation.
We're talking about traditional run-of-the-mill M&A acquisitions, two different companies that are in tech doing some sort of business joining each other. In that situation, under the NDA, there is rarely an opportunity or a reason or a need or a necessity to share personal data. At this point, the personal data should not be relevant.
You might have some basic personal data of the people that are communicating, the high-level executives and their business contact information that needs to be shared for communication purposes, but no employee list should be being shared at this point. There should definitely not be any salary associated with employees' names and locations and things like that.
It's not necessary at that point. And let's not forget, majority of global privacy laws require that you have a legitimate documented necessity to have that data, and there's just not necessary under the NDA element.
Ethan Prete: Sure. In the scenario in which you are the seller and you're pushing back on the information being requested as part of due diligence from the buyer. In your experience, what tends [00:14:00] to be the reaction on the buyer side when you do push back? Are they surprised? Are they understanding?
Erin McCurdy: Unfortunately, a lot of times they are surprised. And that's unfortunate because I always say "Don't murder the messenger," right? Like, It's not the I'm giving you information that is law, and I can't change the law. So unfortunately, they are often surprised but easily if you can explain to them, "Listen, why do you need this at this point?
What are you doing with it?" Nine times out of 10, they're gonna give you an answer that's usually under the due diligence or the integration elements, which are the phases coming up. And I simply explain you don't need it for that point. I can share you an aggregated salary cost."
You're gonna need financials, absolutely. Those financials can be aggregated. They don't-- They could be broken down by high regions, but they don't need to be broken down all the way by zip code, right? It just needs to be higher regions for tax purposes. And you can share that. There needs to be absolutely no personal data shared.
Do an aggregation. We've been very successful in having people understand that and be like, "Oh, I get it. No, we don't really need that other information that we're [00:15:00] requesting. We really need it for this purpose, and this will satisfy that." So it just takes an extra level of discussion and a bit... I'm trying to be a very business-friendly attorney, so I try to come on the calls and be very honest and open and say, "Listen, we want this deal to happen.
We want to partner with you, but we just legally don't see the reason to share this. Can we talk about alternatives?" And people are usually pretty open with that
Ethan Prete: Sure. And I was actually gonna call it as well. You mentioned being a business-friendly attorney. Most listeners in the podcast tend to be more senior, but as you called out earlier, we do also get a lot who are coming into this space in the get-go. So would your advice to them be make sure you are also a coach, not just like a naysayer?
Erin McCurdy: For sure. I think that's a lot of in-house attorneys. That's just not special to the privacy realm. I think that transitioning from a law firm position into in-house, which is traditionally how people get to the in-house, having the experience of being a law firm attorney prior to going in-house is invaluable.
You learn so much. You don't get that level of education when you're in-house. There's an expectation that you know how to do a bunch of things. So I would advocate that everyone start at a law firm [00:16:00] and then go to the in-house positions. And in doing so, you're all of a sudden need to put on a business hat and a legal hat.
You need to co-wear those, and that's always difficult. So one of the challenges that I struggled with going from the law firm into Dick's was to understand how to be a business-minded, business-friendly attorney that was comfortable making decisions. And it took me a little bit of time to adjust to that, but that's something that I claim as one of my specialties.
I think I'm quite good at making the decision. My statement is, if you get paid the big bucks, you gotta make the decisions. That's just the way that it is. So I make decisions regularly, and I assist business people in making their decisions. It's my job to make sure they're educated enough with factual information to make an appropriate decision.
And if the facts change later, okay, you're still making that decision based upon what's in front of you. So making the decision that's not the letter of the law and it's not completely focused on the business, finding that middle ground is paramount, and that's something that once you find out how to do it, it's your job, I [00:17:00] think, to teach and mentor the junior people in doing so, 'cause that's what's going to make you a successful in-house attorney.
Ethan Prete: I think
Erin McCurdy: my opinion, obviously my personal opinion, obviously my personal opinion, not the opinion to the company.
Ethan Prete: I love that. I imagine it helps like we said before, it helps speed up the entire process in general when you have two counsels who are on the same page as well working towards a common outcome. And if everyone can get that same page quicker, I imagine the deal goes quicker as well.
Erin McCurdy: It does. And it, for me, you can't just say no. That's just not helpful. You're in-house, you're a business person. When you're at the law firm, you're the money maker, and you're the one that they focus on. When you go in-house, you're a cost center, and you need to show your worth. And being a partner and a thought partner and building relationships with your business teams is paramount.
So I don't wanna be there saying, "No, you can't do that." I wanna say that's not the best way to do it. Let's talk about this." And I'm always suggesting out-of-the-box opportunities because there's usually some way to get there. It might not be perfect, but we're not just gonna cut the business off at the knees.
Let's be supportive to them
Ethan Prete: Love that. Absolutely love that. And let's keep moving forward in terms of the process, 'cause I know we mentioned a few different steps. let's go post-signing. So let's [00:18:00] say the acquisition agreement is signed. I know that there is a common misconception that once that agreement's signed, the gates are now open and all personal data can be shared.
But is there a distinction between sharing data for pre-closing diligence versus like an early integration?
Erin McCurdy: Absolutely. You nailed it with that, Ethan. So basically, in this situation, once the agreement is signed, you are doing everything or in preparation of closing. So in this situation, a lot of people believe that, "Hey, we're gonna close. We have this agreement in place that we can share all the data."
The an-- That is an incorrect misconception. It's a misconception. It's an incorrect data. Basically, at this point, both parties are doing due diligence in anticipation of closing, and they all have a lot of reps, warranties, and covenants that they've got to get through. So you want to satisfy and help them get there, but you still have limitations on what you need to share.
So in the personal data realm, for employee data, at this point, you can share name, title, job description, things like that, because they need to [00:19:00] figure out, okay, for due diligence purposes, this person's here. At closing, we're gonna pay them this, and you have to do some things to get prepared for that. So - If they ask, a lot of times this-- the buyer's gonna ask for the personnel file at this point, and there's no reason to send that personnel file.
They don't need to know anything about discipline, any investigations. They don't need to know your Social Security number at this point because it's due diligence. So basically, the question that you're continually asking the buyer is what do you need or what due diligence are you satisfying?
Show me in the agreement what you're trying to do, and let's make sure the data that we're sharing is tied specifically to that. A lot of times, the buyer wants to speed things up, and they want to get right into the integration discussions, and those integration discussions are not right at this time.
There's reps and warranties in that agreement that say you cannot overshare, you cannot begin integration, you cannot share for antitrust purposes. You can't jump the gun, and that's what happens at this phase very regularly. People want to get ready to jump the gun, and you've got to slow [00:20:00] everyone down and make sure you're being very diligent in the information you're sharing tied to a specific purpose
Ethan Prete: And when does that change? So there's a signing process obviously, and then there's the process of getting ready for day one readiness. And so in the final weeks before closing, as the buyer's preparing for that day one, so making sure that their like stock options or grants payroll's being cleared, et cetera, how do they go through the process of sharing data that's required for that day one readiness without violating all the integration boundaries that were set in the pre-closing?
Erin McCurdy: So this is a really tricky gray area. So basically, the three areas we've talked about are the NDA, the post-acquisition document, and then closing. So once the do- deal is closed, I'm gonna jump ahead and then backtrack for a second. Once the deal is closed, you are one company, and you can share the information as much...
The information is permissive to be shared. That is a big deal. Not all companies get there, but not all deals close, but that's what you're hoping for, right? A few weeks before that happens, a lot of times additional information can be shared for day one [00:21:00] readiness.
Day one readiness is exactly what you said. I'll use our example. So on day one, the Ansys entity ceased to exist, and then Synopsys was acquiring. We became Synopsys employees, right? That's not exactly how it happened, but I'm just using a hypothetical here. So at that point, we needed to be paid out stock, or we needed to get a salary information.
So prior, under the due diligence efforts, I didn't want to share the Social Security number of my employees with them because they didn't have a need to use it. They didn't need it. There was no necessity to it. But at that point, when you're coming into the day one readiness, yeah, it's just technology systems aren't instantaneous.
It takes a few weeks for them, for the payroll and the HR systems to be updated with that information so that information could flow on day one. So this is a really gray area, and what we did, and which I think it's very important, is that you have to do a legitimate interest assessment. You do an LIA.
In that situation, you are going to share additional information at the eleventh hour for this specific purpose. That information could not be [00:22:00] fed into all of the systems. They could be fed into the payroll or the stock systems. It's very limited. So as long as you document the need for it, and there is a necessity, they need to be ready for day one.
So there's a couple things that go into play here in addition to the LIA. So you need to know that you are at the end and getting re-really close to closing. This is a hard thing. You don't have a crystal ball. You don't know. When you're waiting on a dozen different regulatory approvals, you certainly can't take those steps when none have come in.
When all of them have almost come in and there's just one lingering out there and you think you're gonna get it, like at that point when the tables turn and it's not if we close, it's when we close, is when that becomes appropriate. When you truly believe that you are at the eleventh hour and you're prepping for those situations.
Once again, you have to document limit it to day one readiness only. And if you don't close, then you have to have a clause in there that's been signed that says they'll immediately delete and redact - all the information. But that's day one readiness, and it's extremely important. They need to [00:23:00] be ready for it, so it's very defendable to be able to share that data at that point
Ethan Prete: Yeah, that makes a lot of sense. And you mentioned you had a comment in there that mentioned the, the technology a-as you're thinking about things like Social Security numbers being shared over because you're thinking logically to say now is an appropriate time because I understand that the technologies are going to take some time to get there.
I think that shows, again, another level of technology understanding and awareness that probably makes you a very business-friendly lawyer as well. One of the questions I actually do have, and shifting topics here a little bit, Erin, is given our focus on this podcast of web privacy, I feel like one of the areas that a lot of buyers overlook in their due diligence process is coming through to actually understand the company's web privacy compliance, their ad tech stack.
So what I'm thinking about is as you've gone through this process when auditing a company's like web properties, including the CMP, the consent management platform, or any third-party trackers, do you feel like there's a best practice or something that you would recommend to people?
Erin McCurdy: So when we were on the Ansys side, we had an entire process built for [00:24:00] integrating companies, and it started with my team working very closely with the acquired or the acquiring company who we're buying. And we would review their privacy notice. We'd compare it to ours. We'd review their cookie policy, their cookie compliance.
There are systems that you can pay to do this very inexpensively to see if they're actually capturing everything properly. We'd review the consent mechanisms, and one thing that we always came through was a surprise from the company that we were purchasing that we wouldn't just take their, all that personal data and dump it right into our CRM platform because it was collected under a different privacy notice, and the marketing consents are tied specifically to companies.
So you can't automatically assume that marketing consent covers your new company. It's not. Asset share deals, there can be a little bit of difference if the controller's not changing. But largely, when you're purchasing and the controller is changing, it's a situation that you have to monitor. So we were very ca- we were often very careful with that.
Same thing with Synopsys. We've had these discussions on this side as well. You have to be very cautious of [00:25:00] transferring that data. So for me, I would always say, "Listen, the fact that Synopsys can pur- or Ansys purchase this company and has the right to own this data does not automatically give them the right to communicate with them for marketing purposes."
Transactional communication's separate and apart. Those are done. Those are related specifically to the products being purchased by the whatever company owns them can send those. I'm talking about the marketing purposes and the ability to opt in for the specific companies. So it's a big misconception that people think you can just drop that data right in.
You cannot. You have to do an entire analysis and mapping to understand, can this data come in? If it comes in should it be marked with which opt-ins? You have to have a very detailed CRM process that can track that. And if they can't track opted into certain companies and certain companies can message them, then you can't dump that in.
You have to keep that as separate and apart CRM.
Ethan Prete: Yeah, it makes sense. This is an area where, again I live my everyday life as observe point of we come to people. Typically, what we'll do [00:26:00] for a lot of our friends and people we meet along the way is we'll generate a report card from them of their third-party technologies, of their consent management tool, and give them grades, literally report card of here's how you stack up against the Fortune 1000, here's a benchmark for you.
And a lot of times the reaction is surprise. And you took it a step further down to the data side as well, which I think, again, as a business-friendly attorney, as you're talking to groups like marketing who are probably hearing this for the first time, assuming they've never been through a large acquisition, what tends to be their response when you walk through like you can't just merge those databases?
Erin McCurdy: It is shock and awe. They're like, "What do you mean we can't?" And then my question becomes more practical. Let's be thoughtful about this. Who's actively engaging? 'Cause most likely they have some people that opted in 2007 and haven't interacted with a message ever. So you can boast huge marketing databases, but let's be honest and talk about who you're actually transacting with and who's opening and interacting with you.
So we start there, and it... They calm down a little bit, and then we have conversations about, "Okay well, if you are going to keep a separate website, a separate product, and your product's [00:27:00] not getting integrated into one of ours, you can keep your CRM. Keep your CRM separate and apart and continue with your contracts and continue to market with them."
A lot of times we would let that happen. We would update the privacy notice at some point. Some point after integration, we'll update the privacy notice for it because at some point either they're a subsidiary or they're a product that we have purchased. But if that product is separate and apart website and separate apart product, we have no problem letting them continue to market to their old list.
And then once we change the privacy notice, all new opt-ins are for all of the brands, so it's it would be a Synopsys opt-in or an Ansys opt-in, and then they can communicate with them as well. So they end up having a bifurcated process, and they could, if they wanted to, choose to send an email out to that pr- previous marketing list and say, "Hey, we've been acquired.
Would you like to opt in over here?" We always give them that option. Very low opt-in rates, so they don't... A lot of p- companies don't like to do that. But there's... As long as you don't put, "Opt in or we're gonna stop marketing to you," as long as there's no [00:28:00] ultimatum there, you can continue to populate that into different emails once in a while when you're sending it out.
We don't mind that. We like encouraging people to cross over to the new one, but we don't force it. The only time we force it is if the website is going away and the product is being sunsetted or integrated into their project, product, then we don't let them have that option. We do force the recasting, but
It's very limited situations. We like p- our marketing teams to thrive with what they've cultivated and have the ability to utilize that, so we try not to take that away from them. We try to give them options.
Ethan Prete: And that regulation or that, that process of re-authentication is independent of location on Earth, right? Like it's not just a GDPR thing, it's everywhere.
Erin McCurdy: It's most, almost all countries have some sort of a B2C or B2B law relating to marketing opt-ins or call them electronic communications. In the US we have two laws. We have one for texting, one for email, CAN-SPAM and TCPA. But outside of it, almost all other countries treat electronic communications the same.
And there are a few countries that might not require an opt-in, getting less and less by the day most companies require [00:29:00] that. Canada's the most restrictive. You have to actually have the physical address in your opt-in, so we use that as our global one. Almost all of them require that you have an unsubscribe link right in your opt-in as well.
So there are different global variations, but you can come up with a lor- with a global one to be used
Ethan Prete: Yeah, that makes sense. I as again, as a marketer, that Canadian email law is one I'm very familiar with. So
Erin McCurdy: There you go
Ethan Prete: Big fan. How would you counsel like a deal team if they came across dark patterns or non-compliant web analytics trackers on the seller side so that you're about to acquire this company what would you do or what would you counsel them to do as part of that due diligence process before the acquisition is finalized?
Erin McCurdy: So one of the things we do is look at their privacy notice and look at our privacy notice. And sometimes we've come across situations where that privacy notice is so restrictive that we can barely even transfer the data. So we just have open and honest conversations. Seven times out of 10, the privacy notices are industry standard, you can actually have the data.
But when you actually find negative things in there, we counsel them and say, "Listen, this data is not good. We are [00:30:00] not willing to put this into our system. They don't have the proper consent to have this data. They've overreached, they're not using it for the right purpose, and we'll make them cut the data."
They might be able to keep the data on their system, but we won't let them bring it over. It's not often that happens. We've been... Very reputable companies are being purchased, so if it is something that's bad, it's usually something bad with the marketing opt-in, that it wasn't an appropriate opt-in, that we can't count as an opt-in, or the opt-in didn't look voluntary, it looked forced 'cause they were signing up for a webinar, so we won't take those opt-ins.
So it's much more really in the marketing opt-in space that we find that we can't take some of the data. But we've definitely been in situations that we have to say, "No, this data can't come over, it's not legitimate." We're looking at everything. We're trying to be as comprehensive as possible with the zone and the view of we want this data.
We want our teams to have it. We want them to market to people. But we really only wanna market to people that wanna hear from us. So if somebody is blind to it and they don't want that communication, they're not who we're looking for anyway. So we try to weigh the guidance that we're giving.
But the fact was these people didn't [00:31:00] really sign up for this. They didn't know. They bought, purchased this list of data. These are really good leads, things like that.
It's not always a good message. I deliver bad news regularly, but I try to do it with a smile.
Ethan Prete: And there's our business-friendly attorney right there with a smile. I, it makes, it makes sense to me. Again, I'd probably be the one who pushed back on you if we worked together, unfortunately. But but I do understand. I often try and explain it as you're choosing to have liabilities living in your database.
You're choosing to have liabilities live on your website, which is your most public-facing entity, and why not make that change? In fact, as I've heard people talk, they're always looking through ways of justifying various investments or expanding teams, looking for resources when it comes to things like the web side of their privacy.
Have you ever seen an M&A deal that was affected or slowed down or at risk because of the privacy policy? What level of threat does that typically pose?
Erin McCurdy: So before I answer that, I'm gonna say that I always make a statement that I reserve the right to get smarter, and I'm gonna steal your one statement about liabilities living in your website. I loved that one, so I'm gonna steal that from you, Ethan, if you don't [00:32:00] mind. Okay. So I get asked this question pretty regularly, and I have to say, I don't think that the privacy matters really slow down the deal.
If the personal data is not the data that they're purchasing. We're purchasing software, we're purchasing s- people's resources, we're purchasing some technology that we want. The personal data is just coming along with it, right? So the deal's not gonna be slowed down if we can't transfer their marketing database into our marketing database, if they have to keep a separate database.
We might say, "Hey, this information isn't correct. You've got to keep it separate. We can't merge it." That's what... there's an easy fix to it. It's not like it's a hard no. I've never come across a situation when it's been a hard no because of the personal data. Employee-wise, there's so many laws that the HRIS systems are abiding by.
Regardless if you identify them, you can remedy them on our side. So we might inherit the historic issue, but we're gonna fix it go forward, which is what a regulator wants to see. So I've never seen us slow down or s- stall an agreement. That being said, I'm sure a lot of people have, and they might disagree with that, but in my experience, I have not.
But also, you have deal [00:33:00] counsel out there, and they deal with these things every day, and they have a privacy deal counsel that's leading. So you have someone above you that is giving you cover on the decisions. I wanna be in the mix, I wanna be informed, and I'm always there as a partner, but you still have the ability to have some cover there, which is always nice.
Ethan Prete: Sure. And I appreciate the creativity, obviously. So selfishly, I'm actually gonna ask as you're thinking through, obviously like we said your background is not, you're not a technologist by trade. You've picked up a lot of things along the way, obviously. But as you think about, again, working with the marketing team, whether in the M&A cycle or not, you've mentioned a lot of different regulations and things.
What is your advice to people who are trying to get the empathy? Again, they don't understand necessarily the scope always, 'cause why would they? They don't always understand the technology, but how do you get to that place where you can be an enabler rather than like a someone who's kinda just the naysayer?
Erin McCurdy: So I always make the joke that the CISO and the cyber team are always my best friends. I go into a company and I seek them out. They work in different offices. I ask for an office there, and I work with them one day a week. So my job is to be there and to be their colleague, to [00:34:00] have lunch with them, to learn from them, and that's how I learn every day.
When you're in meetings, like if we have an on... we're onboarding a new vendor and we don't understand the data flows, like I wanna be on the call when those are being detailed through between the IT engineers and the stack and the, and cyber team. Like I wanna be there. So you have to insert yourself, and it's time-consuming.
Like I can't be everywhere at once, you have to pick and choose, but I, that, I instruct my team to do the same, and that's how we begin to learn. You can't sit in your office and dictate. There's just no way you can do that when you're an in-house privacy counsel. They just... you need to know. You need to work with them, and then when they realize that you are not the department of no and that you're willing to, "Ah, let's take a risk here.
Let's... this isn't a really high risk area. It's, we can get comfortable with this disclosure, and we'll put this pop-up here," and that you're working with them to get where they need to be, then all of a sudden you're invited to the table before the decisions are made, and that's where is my bread and butter.
I want in those staff meetings with you. I wanna [00:35:00] talk through when someone has a random idea, I wanna be like, "That's a great idea, but California has this thing that says this, so let's make sure we do it this way." Like things like that. So it is all about making yourself viewed as a service partner and not as the attorney.
I always say that my job is to support you, what do you need from me? And if you take that approach and you don't sit in an ivory tower, it is very well received. I'm a partner to them. Like my job is to make them do their job more efficiently and compliantly
Ethan Prete: Wow. I hope everybody heard that, 'cause that's what I would
Erin McCurdy: That's how I approach life though.
Ethan Prete: As a marketer, like I said, selfishly I'd love to hear it. Erin, I feel like I'd be remiss to not bring up some of your thought leadership. So I actually, in front of me right now, I actually have one of the papers that you co-authored.
And from my observations, and I read this before we jumped on today, but one of the things that I noticed was that there was not a single em dash, which leads me to believe that you actually wrote this thing, and it is awesome.
Erin McCurdy: I wrote every bit of it. I didn't even use Copilot to put through. I don't do it. I don't need it. I do use Copilot for certain limited things, but I don't want [00:36:00] it to appear as if it was written by someone else. I drafted that out in a day. I just put my thoughts... 'Cause I had been on a-- I did a CLE presentation at the IAPP on this topic, and the three of us that did that presentation were asked to do this paper.
So we're co-authoring it together, and I wrote every word of that, as did my colleagues that wrote their parts
Ethan Prete: I love it, and it's not even my area of expertise, but I was very impressed and I love that you guys took that challenge on. Are there any of the big edge cases you wanna call out from your paper to the audience today? The-- I know it covers a few different gray areas, but is there anything specific that your playbook you feel like you wanna add into it?
Erin McCurdy: So the one thing that we get asked very regularly is, how do you prepare for an M&A transaction? And by the time the deal sheet hits you, it's too late from a privacy perspective. You have to be prepared beforehand, okay? So one of the things we can say is When I first get to a company like I'm doing with Synopsys right now, I wanna understand their data mapping.
Do they have their data mapping accurate? Is it done by function? Is it done by group? How is it organized? Do we have data domain [00:37:00] owners? Who's responsible for updating this? What data is being shared where? Do you have a data classification policy? If so, is it classified within this? Do you know where the personal data is?
You know where the government data is? Those are the first things. So those things should be done whenever a privacy officer gets to a company, that should be one of your first steps. I thought Ansys was too big to be acquired, and we clearly weren't, so I wasn't prepared for an acquisition. But we already had these things in place.
And the other thing besides the data mapping I'd like to stress are the ROPAs. ROPAs, records of processing, they might be called different things in different countries, but that is your bread and butter to how to properly evidence that you're processing personal data properly. I don't know how you do it without having a baseline of ROPAs across the company, DPIAs when they're necessary.
I know they're called different things in different areas, but that's necessary. If you have those things, that's what the buyer's gonna wanna know. They're gonna want your data mapping, they're gonna want your ROPAs, and they're also gonna wanna know what previous cyber incidents you have had.
So I'm stealing that from a different part of the paper. Someone else authored that part, so I don't wanna take credit for [00:38:00] it, but a friend of mine authored that, and those are such true statements. So I do echo them, but it wasn't my thought process that wrote that part.
Ethan Prete: Go find her on LinkedIn, follow her. You'll probably see her speaking at a lot of events coming up, including, I know you just spoke at IAPP. Maybe we'll get another invitation there
Erin McCurdy: I would love to speak again next year. I absolutely loved doing it. So I did a panel presentation. I'd like to do one on my own, but we'll see. I loved my panel. My panel was great. I would re-present with that panel in a heartbeat
Ethan Prete: I hope it happens. We're big fans of IAPP as well. We'd love to see you there. Erin, I know we're coming up on time here. So I've been taking some notes here, and some of the key takeaways I have, and I have about four or five of them-ish. You're gonna hate my shorthand 'cause I know you know these things better than me.
But the first one that I thought of was establishing legal prerequisites first. So never sharing personal data at any deal stage without an executed DPA, which I know you talked about at the very beginning of our podcast today. Very important. The second one was strictly separate diligence from integration.
So again, we talked about even before, even after the NDA, making sure those two things are, not an all-access pass.
Erin McCurdy: Yes
Ethan Prete: Step [00:39:00] three would be the default to aggregation early. So during the initial kickoff discussion, satisfy buyer request using aggregated or de-identified data rather than the individual records.
Erin McCurdy: That's so key. You don't need it until a certain point. If they don't need it, truly understand what they need and then share with them what they need, 'cause if not, you as the seller sharing the data, you have to defend that to a regulator, and I wouldn't wanna be up against when explaining why I shared excess data that wasn't needed
Ethan Prete: Love it. Step four, I had audit web and tracker compliance early. So we talked about web analytics, consent management, consent records, ad tech trackers. All of these carry legal liabilities. They're literally living on the website. So making sure you're not acquiring the data that doesn't grant the automatic consent, and if so, you have to go through the process of re-authenticating those or understanding where the delineations happen.
And then lastly, I had the legally the document for day one readiness. So pre-closing transfers for payroll, equity setup. These must be explicitly backed by a legitimate LIA and making sure they're good to go.
Erin McCurdy: A legit-- an LIA, they're pretty... if you don't have one, just do a [00:40:00] search for them. They're all over the place. It's just the extra level of putting pen to paper for the fact that this isn't integration work. This is excessive due diligence for this one purpose of day readiness. Document it. It'll go a far way.
And don't do it after the fact. Document it before, and then have it in that in that document that says, "If we don't close, you will immediately delete this information." It's very important. That's covered in the agreement anyway, but I like to have it documented there as well, 'cause you're sh-sharing someone's government identification number at this point, and that rises to the level of breach if it's mistreated
Ethan Prete: Sure. Again very important information as well. Something that's gonna also carry liability as you're passing that around. So
Let me ask you this last question, Erin, before I let you go. Just to make sure I'm covering all my bases here so my audience doesn't get mad at me. I don't wanna see any negative comments after this.
So if you were sitting down with a CISO, general counsel, chief privacy officer, anyone in that, related field and they're preparing for a sell-side audit, this quarter, what is the single most important habit that you think they should build into their deal team today?
Erin McCurdy: So it's an understanding of where your data is. That is [00:41:00] what so many companies don't understand. They don't know where their data is. Have a strong IT or cyber professional on that team that understands it and documents it properly. You don't know how to share data. You can't physically share the right data or know that it's comprehensive, complete, or correct if you don't have an idea where it is.
Have an organized data map classification of where your data is. That is the number one thing I think all companies should be doing
Ethan Prete: Absolutely love it. A huge fan as well. Again, this is a space that I work in. So Erin, thank you so much. This was exactly the conversation I was hoping for. For everyone listening, please keep an eye out for the piece that Erin is working on. It's gonna be awesome. Go follow her on LinkedIn, Erin McCurdy.
You will find her on LinkedIn. She's an easy find, and I'm sure that she'll share it the moment it's live. Thank you all for joining. We're looking forward to it. And again, no em dashes, so you know it's real. Thank you everyone so much for joining the Web Privacy Podcast today, and we will see you all next time.
Thank you